Hacker News new | ask | show | jobs
by notsag-hn 1885 days ago
If that impersonal approach works for you and everybody is happy with it, that's fantastic.

I haven't hired myself but I have worked with people from all over the world with different backgrounds for many years and have had literally zero close cases of anybody misusing an API key on their benefit for whatever reason. It wouldn't have made any sense for them to do so.

And the control I talked about is security logging, monitoring, alerting systems, etc. I've worked for a banking company and also for a fintech one and all the money movement operations were duly logged and monitored. Literally nobody would risk doing anything malicious in an environment like that plus people are happy with their salaries